DNS hijacking

An attack that takes control of the settings that decide how names resolve, such as a DNS server, a domain's registrar account or a device's resolver, to redirect traffic.

DNS hijacking redirects traffic by taking control of the configuration that decides how names resolve. The attacker may take over a DNS server and change its records, take over a domain’s account at the registrar and point the domain to name servers they run, change the resolver setting on a home router, or use malware to change a computer’s resolver. Clients then receive answers from a source they already trust.

That is the difference from DNS cache poisoning, where forged data is slipped into a resolver the attacker does not control. At the registrar or the authoritative server, the change is served worldwide, and the attacker can often obtain certificates for the domain as its apparent owner. DNSSEC detects records forged by an outsider, but it cannot help if the attacker controls the zone or can change its delegation. Defences centre on access control: multi-factor authentication on registrar and DNS accounts, registry or registrar locks, and monitoring that alerts when DNS records change unexpectedly.

Exam relevance: a scenario is likely to describe a domain’s records changed through a compromised account and ask which control would have prevented it. Candidates are expected to separate hijacking (control of the configuration) from cache poisoning (forged data in a cache) and to choose account protection rather than DNSSEC for the first.